Ë
    ”Âiå  ã                   ó  — d Z ddlZddlZddlmZ ddlmZ ddlmZ ddl	m
Z
 ddlmZ ddlmZ dd	lmZ d
dlmZ ddlmZ  G d„ de«      Z G d„ de«      Z edd«       edd«       edd«       ed«       ed«       ed«      gZy)zËauthlib.jose.rfc7518.
~~~~~~~~~~~~~~~~~~~~

Cryptographic Algorithms for Cryptographic Algorithms for Content
Encryption per `Section 5`_.

.. _`Section 5`: https://tools.ietf.org/html/rfc7518#section-5
é    N)Ú
InvalidTag)Údefault_backend)ÚCipher)ÚAES)ÚCBC)ÚGCM)ÚPKCS7é   )ÚJWEEncAlgorithmé   )Ú
encode_intc                   ó(   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zy)ÚCBCHS2EncAlgorithmé€   c                 ó¶   — d|› d|› �| _         d}|j                  ||«      | _        || _        |dz  | _        |dz  | _        t        t        d|› �«      | _        y )NÚAzCBC-HSz9AES_{}_CBC_HMAC_SHA_{} authenticated encryption algorithmé   r
   Úsha)	ÚnameÚformatÚdescriptionÚkey_sizeÚkey_lenÚCEK_SIZEÚgetattrÚhashlibÚhash_alg)Úselfr   Ú	hash_typeÚtpls       úU/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/jose/rfc7518/jwe_encs.pyÚ__init__zCBCHS2EncAlgorithm.__init__   sb   € Ø˜�z ¨	 {Ð3ˆŒ	ØIˆØŸ:™: h°	Ó:ˆÔð !ˆŒà 1‘}ˆŒà  1™ˆŒÜ¤¨3¨y¨kÐ):Ó;ˆ�ó    c                 óÄ   — t        t        |«      dz  d«      }||z   |z   |z   }t        j                  ||| j                  «      j                  «       }|d | j                   S )Nr   é@   )r   ÚlenÚhmacÚnewr   Údigestr   )r   Ú
ciphertextÚaadÚivÚkeyÚalÚmsgÚds           r!   Ú_hmaczCBCHS2EncAlgorithm._hmac+   sY   € Üœ˜C› 1™ bÓ)ˆØ�B‰h˜Ñ# bÑ(ˆÜ�H‰H�S˜#˜tŸ}™}Ó-×4Ñ4Ó6ˆØ��4—<‘<Ð Ð r#   c                 óÖ  — | j                  |«       |d| j                   }|| j                  d }t        t        j                  «      j                  «       }|j                  |«      |j                  «       z   }t        t        |«      t        |«      t        «       ¬«      }	|	j                  «       }
|
j                  |«      |
j                  «       z   }| j                  ||||«      }||fS )a  Key Encryption with AES_CBC_HMAC_SHA2.

        :param msg: text to be encrypt in bytes
        :param aad: additional authenticated data in bytes
        :param iv: initialization vector in bytes
        :param key: encrypted key in bytes
        :return: (ciphertext, iv, tag)
        N©Úbackend)Úcheck_ivr   r	   r   Ú
block_sizeÚpadderÚupdateÚfinalizer   r   r   Ú	encryptorr1   )r   r/   r+   r,   r-   ÚhkeyÚekeyÚpadÚpadded_dataÚcipherÚencr*   Útags                r!   ÚencryptzCBCHS2EncAlgorithm.encrypt1   s½   € ð 	�‰�bÔØ�>�T—\‘\Ð"ˆØ�4—<‘<�>Ð"ˆä”C—N‘NÓ#×*Ñ*Ó,ˆØ—j‘j “o¨¯©«Ñ6ˆäœ˜D›	¤3 r£7´OÓ4EÔFˆØ×ÑÓ ˆØ—Z‘Z Ó,¨s¯|©|«~Ñ=ˆ
Ø�j‰j˜ S¨"¨dÓ3ˆØ˜3ˆÐr#   c                 ó  — | j                  |«       |d| j                   }|| j                  d }| j                  ||||«      }t        j                  ||«      s
t        «       ‚t        t        |«      t        |«      t        «       ¬«      }	|	j                  «       }
|
j                  |«      |
j                  «       z   }t        t        j                  «      j                  «       }|j                  |«      |j                  «       z   S )aD  Key Decryption with AES AES_CBC_HMAC_SHA2.

        :param ciphertext: ciphertext in bytes
        :param aad: additional authenticated data in bytes
        :param iv: initialization vector in bytes
        :param tag: authentication tag in bytes
        :param key: encrypted key in bytes
        :return: message
        Nr3   )r5   r   r1   r'   Úcompare_digestr   r   r   r   r   Ú	decryptorr8   r9   r	   r6   Úunpadder)r   r*   r+   r,   rA   r-   r;   ÚdkeyÚ_tagr?   r0   ÚdataÚunpads                r!   ÚdecryptzCBCHS2EncAlgorithm.decryptG   sÎ   € ð 	�‰�bÔØ�>�T—\‘\Ð"ˆØ�4—<‘<�>Ð"ˆà�z‰z˜* c¨2¨tÓ4ˆÜ×"Ñ" 4¨Ô-Ü“,Ðäœ˜D›	¤3 r£7´OÓ4EÔFˆØ×ÑÓˆØ�x‰x˜
Ó# a§j¡j£lÑ2ˆÜ”c—n‘nÓ%×.Ñ.Ó0ˆØ�|‰|˜DÓ! E§N¡NÓ$4Ñ4Ð4r#   N)Ú__name__Ú
__module__Ú__qualname__ÚIV_SIZEr"   r1   rB   rK   © r#   r!   r   r      s   „ ð €Gò<ò!òó,5r#   r   c                   ó"   — e Zd ZdZd„ Zd„ Zd„ Zy)ÚGCMEncAlgorithmé`   c                 óL   — d|› d�| _         d|› d�| _        || _        || _        y )Nr   r   zAES GCM using z-bit key)r   r   r   r   )r   r   s     r!   r"   zGCMEncAlgorithm.__init__e   s1   € Ø˜�z Ð%ˆŒ	Ø+¨H¨:°XÐ>ˆÔØ ˆŒØ ˆ�r#   c                 ó  — | j                  |«       t        t        |«      t        |«      t	        «       ¬«      }|j                  «       }|j                  |«       |j                  |«      |j                  «       z   }||j                  fS )a  Key Encryption with AES GCM.

        :param msg: text to be encrypt in bytes
        :param aad: additional authenticated data in bytes
        :param iv: initialization vector in bytes
        :param key: encrypted key in bytes
        :return: (ciphertext, iv, tag)
        r3   )
r5   r   r   r   r   r:   Úauthenticate_additional_datar8   r9   rA   )r   r/   r+   r,   r-   r?   r@   r*   s           r!   rB   zGCMEncAlgorithm.encryptk   sl   € ð 	�‰�bÔÜœ˜C›¤# b£'´?Ó3DÔEˆØ×ÑÓ ˆØ×(Ñ(¨Ô-Ø—Z‘Z “_ s§|¡|£~Ñ5ˆ
Ø˜3Ÿ7™7Ð"Ð"r#   c                 óü   — | j                  |«       t        t        |«      t        ||«      t	        «       ¬«      }|j                  «       }|j                  |«       |j                  |«      |j                  «       z   S )a6  Key Decryption with AES GCM.

        :param ciphertext: ciphertext in bytes
        :param aad: additional authenticated data in bytes
        :param iv: initialization vector in bytes
        :param tag: authentication tag in bytes
        :param key: encrypted key in bytes
        :return: message
        r3   )	r5   r   r   r   r   rE   rV   r8   r9   )r   r*   r+   r,   rA   r-   r?   r0   s           r!   rK   zGCMEncAlgorithm.decrypt{   sa   € ð 	�‰�bÔÜœ˜C›¤# b¨#£,¼Ó8IÔJˆØ×ÑÓˆØ	×&Ñ& sÔ+Ø�x‰x˜
Ó# a§j¡j£lÑ2Ð2r#   N)rL   rM   rN   rO   r"   rB   rK   rP   r#   r!   rR   rR   `   s   „ ð €Gò!ò#ó 3r#   rR   r   é   éÀ   i€  i   )Ú__doc__r   r'   Úcryptography.exceptionsr   Úcryptography.hazmat.backendsr   Ú&cryptography.hazmat.primitives.ciphersr   Ú1cryptography.hazmat.primitives.ciphers.algorithmsr   Ú,cryptography.hazmat.primitives.ciphers.modesr   r   Ú&cryptography.hazmat.primitives.paddingr	   Úrfc7516r   Úutilr   r   rR   ÚJWE_ENC_ALGORITHMSrP   r#   r!   ú<module>rd      s‰   ðñó Û å .Ý 8Ý 9Ý AÝ <Ý <Ý 8å %Ý ôD5˜ô D5ôN)3�oô )3ñZ �s˜CÓ Ù�s˜CÓ Ù�s˜CÓ Ù�CÓÙ�CÓÙ�CÓðÑ r#   